This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Failed Code Integrity Checks
Original Source:
[Sigma source]
Title:
Failed Code Integrity Checks
Status:
stable
Description:
Detects code integrity failures such as missing page hashes or corrupted drivers due unauthorized modification. This could be a sign of tampered binaries.
References:
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-5038
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-6281
Author:
Thomas Patzke
Date:
2019-12-03
modified:
2025-01-19
Tags:
-'attack.stealth'
-'attack.t1027.001'
Logsource:
product: windows
service: security
Detection:
selection:
EventID
:
-'5038'
-'6281'
filter_optional_crowdstrike:
param1|contains
:
-'\CSFalconServiceUninstallTool_'
-'\Program Files\CrowdStrike\'
-'\System32\drivers\CrowdStrike\'
-'\Windows\System32\ScriptControl64_'
filter_optional_sophos:
param1|contains
:
'\Program Files\Sophos\'
condition
:
selection and not 1 of filter_optional_*
Falsepositives:
-Disk device errors
Level:
informational